CVE-2026-73335 PUBLISHED

Assigner: jpcert
Reserved: 12.08.2026 Published: 26.08.2026 Updated: 26.08.2026

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A malicious application installed on the user's Android device may exploit the affected application's functionality through an Intent, potentially allowing arbitrary JavaScript to be executed within the affected application.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
CVSS Score: 4.6

Product Status

Vendor Digital Agency
Product Android App "Myna Point"
Versions Default: unaffected
  • affected from 0 to 2.0.6 (incl.)

References

Problem Types